US2008089494A1PendingUtilityA1

System and Method for Securing a Telephone System Comprising Circuit Switched and IP Data Networks

Individually held — no corporate assignee on recordPriority: Jun 23, 2005Filed: Nov 8, 2007Published: Apr 17, 2008
Est. expiryJun 23, 2025(expired)· nominal 20-yr term from priority
H04L 41/28H04L 63/0209H04L 63/029
17
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention discloses a system and method for securing a telephone system comprising a circuit switched network and an IP data network. The system comprises a first firewall, between an internal IP data network and an external IP data network, for protecting the internal IP data network against intrusion; a second firewall, between the internal IP data network and a circuit switched network, for preventing intrusion originated in the external IP data network into the circuit switched network; a third firewall for protecting voice-over-IP phones against intrusion from the external IP data network; intrusion detection system (IDS) probes and time-division multiplexing (TDM) voice probes for extracting information about voice-over-IP calls over the internal IP data network; a Session Initiation Protocol (SIP) proxy server for managing voice-over-IP call control signals; and a security supervisor for managing the operation of the firewalls and the IDS and TDM voice probes.

Claims

exact text as granted — not AI-modified
1 . A system for securing a telephone system comprising at least one circuit switched network and at least one IP data network, the system comprising: 
 a first firewall, situated between an internal IP data network and an external IP data network, for protecting the internal IP data network against intrusion;    a second firewall, situated between the internal IP data network and a circuit switched network, for preventing intrusion that is originated in the external IP data network into the circuit switched network;    a third firewall for protecting a plurality of voice-over-IP phones against intrusion from the external IP data network;    at least one intrusion detection system (IDS) probe and at least one time-division multiplexing (TDM) voice probe for extracting information about voice-over-IP calls over the internal IP data network;    a Session Initiation Protocol (SIP) proxy server for managing voice-over-IP call control signals; and    a security supervisor for managing the operation of the first, the second and the third firewalls and the at least one IDS probe and the at least one TDM voice probe.    
   
   
       2 . The system of  claim 1 , wherein the first firewall manages one or more communication ports to control exchange of voice data between the internal IP data network and the external IP data network.  
   
   
       3 . The system of  claim 1 , wherein the second firewall manages communication ports to control exchange of voice data between the internal IP data network and the circuit switched network.  
   
   
       4 . The system of  claim 1 , wherein the third firewall manages communication ports to control voice data to and from the plurality of voice-over-IP phones.  
   
   
       5 . The system of  claim 1 , wherein the at least one IDS probe extracts information from SIP call control signals.  
   
   
       6 . The system of  claim 1 , wherein the at least one TDM voice probe synchronizes with the security supervisor to determine whether to deny a call control request from a caller by blocking it from a firewall.  
   
   
       7 . The system of  claim 1 , wherein the SIP proxy server comprises a registration server and an authentication server.  
   
   
       8 . The system of  claim 7 , wherein the SIP proxy server further comprises a detective module.  
   
   
       9 . The system of  claim 8 , wherein the detective module extracts caller and callee information from the call control signals.  
   
   
       10 . The system of  claim 8 , wherein the detective module is pre-configured with a set of static rules for detecting predetermined malicious attacks.  
   
   
       11 . The system of  claim 7 , wherein the registration server records a predetermined association between the user/phone number and the address of a SIP phone.  
   
   
       12 . The system of  claim 7 , wherein the authentication server authenticates the caller's identity.  
   
   
       13 . The system of  claim 1 , wherein the security supervisor comprises an audit supervisor, an expert system, a database, and at least one security module.  
   
   
       14 . The system of  claim 13 , wherein the audit supervisor analyzes the capabilities of the SIP proxy server and the plurality of SIP phones.  
   
   
       15 . The system of  claim 1 , wherein the security supervisor receives caller and callee information that is extracted from voice data by the IDS probes, the TDM voice probe, and the SIP proxy server.  
   
   
       16 . A method for securing a telephone system with at least one circuit switched network and at least one IP data network by using one or more firewalls to protect voice-over-IP calls, the method comprising: 
 dividing the telephone system into a plurality of security zones and assigning a security level to one or more communication devices in the plurality of security zones;    verifying that a caller initiating at least one call control signal and a SIP proxy server are originated from at least one trusted domain and that the caller is allowed to establish a voice-over-IP call with a callee in the telephone system based on a security rule;    confirming a caller's authenticity with the SIP proxy server via a secured channel that is established by using the one or more Secure Sockets Layer certificates;    opening at least one communication port on the one or more firewalls for the voice-over-IP call; and    monitoring the at least one call control signal and the voice-over-IP call to gather information about the voice-over-IP call.    
   
   
       17 . The method of  claim 16 , wherein the dividing the telephone system into the plurality of security zones depends on a location and importance of the user of the communication device.  
   
   
       18 . The method of  claim 16 , wherein the confirming the caller's authenticity is carried out using a proprietary dialog between the SIP proxy servers of the caller and callee.  
   
   
       19 . The method of  claim 16 , wherein the communication ports must not be numbered sequentially.  
   
   
       20 . The method of  claim 16 , wherein the monitoring the at least one call control signal and the voice-over-IP call further comprises: 
 examining the at least one call control signal to detect spoofing of the information;    monitoring the content of voice data to detect overloading of the at least one IP data network by attackers;    preventing a communication device from being stalked by attackers; and    protecting a plurality of servers in a telephone system against denial-of-service attacks.    
   
   
       21 . The method of  claim 20 , wherein the examining the at least one call control signal further comprises: 
 verifying that a caller is authorized to re-direct a call to another communication device or another area;    verifying that an incoming call is originated from the caller in a confirmed security zone;    verifying that the at least one call control signal traverses a coherent path; and    verifying that a modification of the properties of an on-going voice-over-IP call is authorized.    
   
   
       22 . The method of  claim 20 , wherein the monitoring the content of voice data includes analyzing and comparing a temporal property of a voice data flow with a pattern associated with the voice codec.  
   
   
       23 . The method of  claim 20 , wherein the preventing the communication device from being stalked by attackers depends on collecting statistics including the number of calls within a predetermined period, the average time interval between two consecutive calls, and the identity of the caller.  
   
   
       24 . The method of  claim 20 , wherein the protecting the plurality of servers in the telephone system against denial-of-service attacks further comprises: 
 monitoring volume and pattern of on-going calls that enter the telephone system; and    limiting the number of requests that enter the telephone system within a predetermined period of time system and method for securing a telephone system comprising circuit switched and IP data networks.

Join the waitlist — get patent alerts

Track US2008089494A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.